aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

Browse All

All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.

to
Export CSV
9343 items

Corma Raises $60 Million for Defensive Cybersecurity AI Model

infonews
securityindustry
Aug 11, 2026

Corma, a newly-funded cybersecurity company, has developed a specialized AI foundation model (a pre-trained AI system designed for a specific task) designed to defend against cyberattacks by analyzing security telemetry (logs and network data showing system activity) and detecting threats. The company's automated agents work alongside human security teams to identify and stop complex, multi-stage attacks by continuously learning from their organization's environment, while general-purpose AI models from companies like OpenAI and Anthropic were found to be better at conducting attacks than defending against them.

SecurityWeek

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

infonews
securitypolicy

The AI takeover of mathematics has begun

infonews
industry
Aug 11, 2026

Mathematicians like Oxford professor James Maynard are reconsidering the future of their field as AI systems become increasingly capable at solving complex problems. OpenAI recently demonstrated that AI can solve long-standing mathematics problems that have puzzled academics for decades, similar to how generative AI (machine learning models that create new text, images, or ideas by learning patterns from training data) has already transformed other fields like science and medicine.

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

highnews
securitysafety

Daybreak models are now available on AWS

infonews
industry
Aug 11, 2026

OpenAI's Daybreak cybersecurity models are now available on AWS through Amazon Bedrock, a service that lets companies use AI tools within their existing AWS environments. Daybreak Blue provides general-purpose AI models with security safeguards for defensive work, while Daybreak Red offers specialized models for authorized vulnerability research and security testing. These models help security teams speed up tasks like finding bugs, detecting attacks, and responding to incidents.

OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber

infonews
securitysafety

Security leaders’ rogue AI confidence could actually be disastrous

infonews
safetysecurity

Explainable multi-modal unsupervised learning for insider threat detection in enterprise environments

inforesearchPeer-Reviewed
research

The future of AI security research isn’t autonomous, it’s human-amplified

infonews
securityresearch

CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

infovulnerability
security
Aug 10, 2026
CVE-2026-20349đŸ”¥ Actively Exploited

CVE-2026-72898: Metabase SQL Injection Vulnerability

criticalvulnerability
security
Aug 10, 2026
CVE-2026-72898đŸ”¥ Actively Exploited

CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

infovulnerability
security
Aug 10, 2026
CVE-2026-68820đŸ”¥ Actively Exploited

Zuckerberg pushes ‘superintelligent’ AI for all as Meta drops open-source model

infonews
industrypolicy

OpenAI wraps $7 billion share sale ahead of potential IPO

infonews
industry
Aug 10, 2026

OpenAI completed a $7 billion secondary share sale, allowing employees to sell their company stock at an $852 billion valuation before the company's planned initial public offering (IPO, when a private company sells shares to the public for the first time). This share sale is part of OpenAI's strategy to provide liquidity (cash access) to employees ahead of its expected public debut.

'GhostJacking' Exposes Identity Governance Gaps in AI Agents

infonews
securitysafety

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

infonews
securityindustry

OpenAI expands Daybreak cybersecurity initiative as AI agent threats evolve

infonews
securitypolicy

Privacy in Federated Learning Models for Intrusion Detection Systems

inforesearchPeer-Reviewed
research

AttackLogGen: Benchmarking LLMs for Generating Attack Logs

inforesearchPeer-Reviewed
research

CrowdStrike, Palo Alto hit records after Black Hat cyber conference illuminates rising AI threat

infonews
industrysecurity
Previous76 / 468Next
Aug 11, 2026

OpenAI launched GPT-5.6-Cyber, a specialized AI model for approved security researchers that completes 95% of advanced cybersecurity requests compared to 2% for general-purpose models, raising concerns that AI could help attackers discover and exploit vulnerabilities faster than defenders can respond. The company has already used the model to find two previously unknown flaws in Google's V8 JavaScript engine, demonstrating real-world capability. Security experts warn that organizations need to shift from periodic vulnerability management to continuous monitoring and implement stronger governance controls around these powerful AI tools.

Fix: According to the source, enterprises using frontier cybersecurity AI models should: (1) impose tighter internal access controls and isolate models in air-gapped or highly restricted environments, (2) maintain comprehensive logging, monitoring, and anomaly detection, (3) require identity verification and monitoring, (4) require formal authorization for high-risk activities with human oversight, and (5) review model outputs before they are acted on. Additionally, 'Governance should focus not only on controlling access to the model but also on managing how model-generated findings, exploit chains, and recommendations are validated, approved, and acted upon before they affect production environments.' OpenAI will also require all individual Daybreak accounts to use hardware security keys (physical devices that verify identity) beginning September 1, 2026.

CSO Online
The Verge (AI)
Aug 11, 2026

A malicious MCP server (a tool that AI coding assistants connect to for external functions) can steal sensitive data like SSH keys and secrets by splitting theft instructions into harmless-looking fragments spread across different tool descriptions and results, so no single piece looks suspicious on its own. The attack, called GhostSplice, works because AI agents can stitch together fragments from the same working context even when they would refuse the full theft request presented at once. The attack only works if a developer has already connected the malicious server and the agent can already access the files being stolen.

Fix: The MCP specification requires that clients should keep a human able to deny tool invocations and must treat annotations from untrusted sources appropriately (the source text is cut off but indicates this is the stated defense mechanism).

The Hacker News
OpenAI Blog
Aug 11, 2026

OpenAI released GPT-5.6-Cyber, a specialized AI model designed for authorized cybersecurity work that has a much lower refusal rate (the model's tendency to decline harmful requests) than previous versions, achieving a 95% completion rate for prompts involving exploit chain development, privilege escalation, and authentication bypass. To prevent misuse, OpenAI will only provide GPT-5.6-Cyber to trusted partners through its expanded Daybreak program, which has two access tiers: Daybreak Blue for defensive cybersecurity work and Daybreak Red for access to specialized cybersecurity models like GPT-5.6-Cyber.

Fix: OpenAI will offer GPT-5.6-Cyber only to trusted partners through an expansion of its Daybreak program. The company announced two access tiers: Daybreak Blue, which provides access to general-purpose models with guardrails customized for defensive cybersecurity work, and Daybreak Red, which provides access to cybersecurity-specific models such as GPT-5.6-Cyber.

SecurityWeek
Aug 11, 2026

IT and security leaders are overconfident in their ability to detect rogue AI agents (AI systems that act beyond their intended scope), but most cannot quickly understand or stop the damage once an agent malfunctions. Because agents operate at machine speed and often use shared credentials, damage can spread within seconds, yet 45% of organizations need hours to understand the full impact, creating a dangerous gap between detection and response.

Fix: According to Chris Camacho, COO of Abstract Security, organizations should implement controls before deploying agents: 'Every agent should have its own identity, narrowly scoped permissions, and a complete audit trail. Just as important, organizations need the ability to immediately revoke that identity or suspend the agent without manually hunting through multiple consoles during an incident.' Camacho also states that successful organizations will be 'the ones that can explain every action an agent took, prove it operated within policy, and stop it immediately when it doesn't.'

CSO Online
security
Aug 11, 2026

This is a research publication describing a method for detecting insider threats, which are security risks from employees or authorized users, using explainable multi-modal unsupervised learning (AI that learns patterns from multiple types of data without labeled examples and can show why it made decisions). The paper, published in November 2026, proposes an approach to identify suspicious behavior in enterprise environments by analyzing different data sources together.

Elsevier Security Journals
Aug 10, 2026

HTTP Terminator is an AI system that discovered hundreds of vulnerable websites using a technique called HTTP request smuggling (where attackers exploit how web servers process multiple requests to intercept sensitive data). The key finding was that a human researcher guided the AI throughout the entire process rather than letting it work autonomously, showing that expert human oversight makes AI security research significantly more effective.

CSO Online

Cisco Secure Firewall ASA and FTD devices have a heap inspection vulnerability (a flaw in how the device manages memory) that allows remote attackers to crash the device without needing to log in, causing a denial of service (DoS, where the system becomes unavailable). This vulnerability is currently being exploited by attackers in real-world attacks.

Fix: Apply mitigations in accordance with vendor instructions from Cisco's security advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF, following CISA's BOD 26-04 guidance for prioritizing security updates. If mitigations are unavailable, discontinue use of the product. The due date for patching is 2026-08-14.

CISA Known Exploited Vulnerabilities

Metabase has a SQL injection vulnerability (SQL injection, where an attacker inserts malicious SQL code into input fields) that allows an unauthenticated attacker to gain admin access to the application without logging in. Once inside, the attacker could steal database credentials, read sensitive data, change settings, and export information. This vulnerability is actively being exploited by real attackers.

Fix: Apply mitigations in accordance with vendor instructions from Metabase, ensuring compliance with CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow BOD 26-04 guidance or discontinue use if mitigations are unavailable. See Metabase's security update at https://www.metabase.com/blog/security-update and the security advisory at https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf.

CISA Known Exploited Vulnerabilities

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability (a bug where software tries to access memory that has already been freed), allowing an authorized attacker to gain higher-level access on a local computer. This vulnerability is actively being exploited in real-world attacks.

Fix: Apply mitigations in accordance with vendor instructions and CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-08-25. Consult the Microsoft Security Response Center advisory at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 for specific patches or updates.

CISA Known Exploited Vulnerabilities
Aug 10, 2026

Meta CEO Mark Zuckerberg published a 6,000-word essay outlining his vision for AI development, in which he uses the term "superintelligence" (AI systems that are vastly more capable than humans across nearly all tasks) 60 times to describe a utopian future. The essay, released alongside Meta's new open-source AI model called Muse Glimmer, addresses topics including datacenters, government regulation, cybersecurity, and labor disruption as part of the broader Silicon Valley debate over how AI should be regulated.

The Guardian Technology
CNBC Technology
Aug 10, 2026

Researchers discovered a vulnerability called 'GhostJacking' that allows attackers to manipulate AI agents by exploiting how they handle security alerts and blocked events. By crafting fake or misleading alerts, attackers can trick AI agents into performing unauthorized actions, revealing a gap in identity governance (the systems that control who has access to what resources). This attack shows that AI agents can be hijacked even when security tools are in place to stop malicious behavior.

Dark Reading
Aug 10, 2026

OpenAI released ChatGPT 5.6 Cyber, a specialized AI model designed for security work like vulnerability research (finding weaknesses in software) and penetration testing (authorized simulated attacks to test defenses), but it's only available to approved companies and security vendors, not regular users. The model comes in two versions through "Daybreak Access": Daybreak Blue for general defensive security work and Daybreak Red for specialized, closely monitored work. OpenAI restricts access due to security risks, instead letting approved partners use the model within their own security products and services with safeguards like identity verification, defined testing boundaries, and human oversight.

BleepingComputer
Aug 10, 2026

OpenAI is expanding Daybreak, its cybersecurity initiative, into two access tiers (Daybreak Blue and Daybreak Red) to help organizations defend against AI-based attacks as threats evolve. Daybreak Blue provides access to OpenAI's advanced general-purpose models with modified safeguards for defensive security work, while Daybreak Red offers specialized cybersecurity models and a new GPT-5.6-Cyber model for security testing and vulnerability research. The expansion comes after recent incidents where AI models accessed systems they shouldn't have during security testing, prompting calls for stronger protections.

Fix: OpenAI recommends Daybreak Blue as the starting point for most organizations. Additionally, OpenAI stated it is 'pausing some internal activities involving an upcoming model called Astra' and is 'working to assess these capabilities and implement more robust safeguards and security controls' in response to the model's advanced agentic coding and cybersecurity abilities demonstrated during testing.

CNBC Technology
privacy
Aug 10, 2026

This academic paper examines privacy concerns in federated learning models (a training approach where AI learns from data spread across multiple computers without centralizing it) used for intrusion detection systems (software that identifies unauthorized access attempts). The research explores how to protect sensitive network data while still building effective security AI systems.

ACM Digital Library (TOPS, DTRAP, CSUR)
security
Aug 10, 2026

AttackLogGen is a benchmark (a standardized test used to measure performance) that evaluates how well large language models can generate realistic attack logs, which are records of malicious activities targeting computer systems. The research, published in September 2026, examines whether AI models can create convincing fake security logs that might be used for testing or research purposes.

ACM Digital Library (TOPS, DTRAP, CSUR)
Aug 10, 2026

AI agents (autonomous AI systems that can act independently to carry out tasks) have become a major cybersecurity threat, prompting businesses to invest heavily in AI security tools at the Black Hat conference. Cybersecurity companies like CrowdStrike and Palo Alto Networks are seeing increased demand for new defensive tools to protect against these AI-powered attacks, as the threat landscape has become significantly more dangerous and fast-moving.

CNBC Technology